b1freearchiver_1.0.37.exe

B1 Free Archiver Installer

Catalina Group Limited

The application b1freearchiver_1.0.37.exe by Catalina Group Limited has been detected as a potentially unwanted program by 8 anti-malware scanners. This is a setup and installation application and has been known to bundle potentially unwanted software. This file is typically installed with the program B1 Free Archiver by Catalina Group Ltd.. The file has been seen being downloaded from b1.org.
Publisher:
Catalina Group Limited  (signed and verified)

Product:
B1 Free Archiver Installer

Version:


MD5:
1d715a95ca4ec998f2aab1676d60791f

SHA-1:
cbf66576d1cf2f6545477351eb62df838a463ffa

SHA-256:
f9848378aa6eea183509a73b5d00fb692a89ce55fa2feb3876fb4e2b55b2d752

Scanner detections:
8 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 6:37:48 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Malware-gen
2014.9-150527

Bkav FE
W32.HfsAdware
1.3.0.6379

ESET NOD32
Win32/4Shared.T potentially unwanted (variant)
9.11196

McAfee
Artemis!1D715A95CA4E
5600.6752

Reason Heuristics
PUP.Catalina.Installer
15.5.27.21

Rising Antivirus
PE:PUF.4Shared!1.9C25
23.00.65.15525

Trend Micro House Call
TROJ_GEN.F47V0926
7.2.147

VIPRE Antivirus
Trojan.Win32.Generic
37680

File size:
1.5 MB (1,573,224 bytes)

Product version:
1, 1, 8, 0

Copyright:
Copyright (C) 2013

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\b1freearchiver_1.0.37.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
9/26/2012 9:56:54 PM

Valid to:
9/26/2013 9:56:54 PM

Subject:
CN=Catalina Group Limited, O=Catalina Group Limited, L=Kwun Tong, S=Hong Kong, C=HK

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
27B940A1704DC9

File PE Metadata
Compilation timestamp:
4/11/2013 9:48:51 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:TFKYMjx9B+K68TbRk2boDOvJ9fp66iKWS7sH79v9ThQkbeG7y7eYh26wZFHmr9Yb:TFKYMtz+KxTb17vjE60brTmkyG7wj

Entry address:
0x22901

Entry point:
E8, F2, 9E, 00, 00, E9, 79, FE, FF, FF, CC, CC, CC, CC, CC, 8B, 4C, 24, 04, F7, C1, 03, 00, 00, 00, 74, 24, 8A, 01, 83, C1, 01, 84, C0, 74, 4E, F7, C1, 03, 00, 00, 00, 75, EF, 05, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8B, 01, BA, FF, FE, FE, 7E, 03, D0, 83, F0, FF, 33, C2, 83, C1, 04, A9, 00, 01, 01, 81, 74, E8, 8B, 41, FC, 84, C0, 74, 32, 84, E4, 74, 24, A9, 00, 00, FF, 00, 74, 13, A9, 00, 00, 00, FF, 74, 02, EB, CD, 8D, 41, FF, 8B, 4C, 24, 04, 2B, C1, C3, 8D, 41, FE, 8B...
 
[+]

Entropy:
7.3697

Code size:
226 KB (231,424 bytes)

The file b1freearchiver_1.0.37.exe has been discovered within the following program.

B1 Free Archiver  by Catalina Group Ltd.
Publisher's description - “B1 archive is an open archive format, where best proven solutions were improved even more with new original ideas. It's free and available for both personal and commercial use. B1 Archiver is extremely simple to use, you don't need comprehensive manuals or guides.”
b1.org
45% remove it
 
Powered by Should I Remove It?

The file b1freearchiver_1.0.37.exe has been seen being distributed by the following URL.

Remove b1freearchiver_1.0.37.exe - Powered by Reason Core Security